THREAT OPS › Threat News › [GHSA] GHSA-7gwp-5pfp-969j (critical) — MLflow: Unauthenticated full-read SSRF in webhook delivery: _validate_webhook_url bypassed via unvalidated HTTP redirects (and DNS rebinding)
[GHSA] GHSA-7gwp-5pfp-969j (critical) — MLflow: Unauthenticated full-read SSRF in webhook delivery: _validate_webhook_url bypassed via unvalidated HTTP redirects (and DNS rebinding)
GHSA-7gwp-5pfp-969j Severity: critical CVE: CVE-2026-64849
MLflow: Unauthenticated full-read SSRF in webhook delivery: _validate_webhook_url bypassed via unvalidated HTTP redirects (and DNS rebinding)
### Summary The default MLflow Tracking Server (`mlflow server`, no authentication, default SQLite backend) exposes the model-registry webhooks API unauthenticated, including a synchronous `POST /a
MITRE ATT&CK techniques
- CredentialsT1589.001
Indicators of compromise
- CVE-2026-64849cve
- CVE-2025-14279cve
- http://169.254.169.254/...`url
- http://127.0.0.1:...`url
- http://169.254.169.254/latest/meta-data/iam/security-credentials/url
- http://127.0.0.1:6379/url
- https://127.0.0.1/url
- https://{{ATTACKER}}/innocenturl
- http://169.254.169.254/latest/meta-data/url
Original source: https://github.com/advisories/GHSA-7gwp-5pfp-969j